Near-Term Verification Methods for AI Chip Exports
This report was co-authored by Bruna Avellar.
AI chip export controls are an indispensable tool for the United States to shape the trajectory of frontier AI development, but their effectiveness depends on how well they are enforced. Enforcement, in turn, requires the ability to verify compliance with export controls. This report serves as an implementation guide for policymakers seeking to strengthen enforcement of export controls, presenting a menu of near-term verification mechanisms—here defined as implementable in approximately one year—each selected for its feasibility, cost-effectiveness, and potential to serve as meaningful components of an effective export control enforcement regime.
We define “verification” as the process of obtaining information that determines, with a high degree of confidence, whether export controls have been violated. The mechanisms we describe are divided into three categories:
End-location verification ensures that controlled chips remain within authorized locations and/or jurisdictions.
End-user verification ensures the legitimacy of entities that acquire or access compute.
End-use verification ensures that computing power is not being used for prohibited purposes.
Each of these categories is described in a report section, outlining specific verification mechanisms and discussing how they can be implemented within the regulatory framework of the Bureau of Industry and Security (BIS), the U.S. agency that administers and enforces dual-use export controls.
As of July 2026, BIS is facing significant challenges in implementing and enforcing its existing verification methods, largely due to its relatively small budget and outdated technology.¹ The Trump administration has requested $450 million for BIS in fiscal year 2027, but even if forthcoming, this would not fully resolve BIS’s resource gap.² Considering these constraints, the most viable verification approaches today rely on private-sector actors working alongside BIS, leverage existing technologies, and scale without requiring large increases in government staffing.
The verification mechanisms described in the report can each be carried out by one of three actors: BIS itself, through its existing enforcement infrastructure; an exporting company, either voluntarily or as an export condition imposed by BIS; or an independent third-party auditor accredited by BIS, should such an accreditation system be established. An accreditation system for third-party auditors does not currently exist, but it could help scale enforcement, given BIS’s limited resources relative to the volume of controlled items in circulation. A separate IAPS report has described this proposal in detail.³
Verification mechanisms vary considerably in their cost, intrusiveness, and enforcement value. An effective mechanism can provide significant value even if it is not impossible to evade—it can be useful as long as it is effective enough to make it more costly for malicious actors to evade export controls.
For end-location verification, one option is on-site inspections. These are effective but labor-intensive and costly, making them best suited as a targeted mechanism for high-risk exports rather than a routine practice. Another option is remote video inspections or auditor-directed video walkthroughs, which offer a less resource-intensive alternative to physical inspections but are more susceptible to staging or manipulation—for instance, using AI to create synthetic video feeds—than physical visits. A third option is a delay-based mechanism, which provides near-real-time information about a chip’s location by measuring the response delay between chips and trusted landmark servers, leveraging existing chip-level attestation capabilities at relatively low cost. However, this mechanism offers limited visibility during shipping and warehousing, before chips are deployed. These approaches are not mutually exclusive and can be layered, for example using delay-based mechanisms as a first line of detection and triggering video or on-site inspections when anomalies surface.
For end-user verification, enhanced Know-Your-Customer checks—which include automated supply chain risk analysis—can be an effective method to detect concealed ownership structures and prevent restricted entities from acquiring chips through intermediaries. In this approach, exporters⁴ would use specialized platforms to review publicly available information such as corporate filings to identify links to entities of concern, like those subject to specific license requirements per the BIS-maintained Entity List. Although this mechanism works well as a preventive screen to verify the identity of purchasers before export, it cannot be used as an ongoing monitoring tool.
For end-use verification, cross-checking end-use declarations against publicly available information that attest to a customer’s line of business, such as corporate records, can help chip exporters verify that a customer’s declared use is consistent with their actual business activities. This mechanism might also become relevant for cloud providers, should cloud access become regulated under the BIS’s Export Administration Regulations (EAR), as they could perform similar cross-checks on customers.
These mechanisms are, however, designed to detect violations rather than enforce compliance on their own. Robust enforcement systems should pair verification with follow-up investigations whenever there is reason to suspect a violation has occurred, and proceed with enforcement action if a violation is confirmed.
Beyond their use for export enforcement, these verification mechanisms could also serve to monitor compliance with future international AI agreements, which may become necessary to coordinate safety measures across states as advanced AI systems grow increasingly capable and pose growing systemic risks.⁵ Such agreements would require credible monitoring and verification systems to be effective. Developing strong verification mechanisms in the narrow context of export controls provides an opportunity to test the mechanisms that could support broader AI agreements in the future, while still providing immediate value by strengthening U.S. export enforcement.
Click here for a summary of all the mechanisms discussed in this report.
Endnotes
Roberts, “BIS is getting more funding—here's how to spend it.”; Roberts, “BIS should build a lean, mean, data-driven enforcement machine.
U.S. Department of Commerce, “Fiscal Year 2027 President’s Budget Request.”
Aarne and Grunewald, “Export Auditors as Market-Powered Export Enforcement.”
Throughout this report, unless otherwise noted, by “exporter” we mean “exporter, re-exporter, or in-country transferor.” Likewise, by “export” we mean “export, reexport, or in-country transfer.”
Baker et al., “Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment.”